6.4
CVSSv2

CVE-2021-41292

Published: 30/09/2021 Updated: 25/04/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ecoa ecs_router_controller-ecs_firmware -

ecoa riskbuster_firmware -

ecoa riskterminator -